Associated Press and Herald staff
A Washington agency examining how the state fell victim to massive unemployment fraud last year said Monday that files on 1.6 million claims that it obtained for its investigation have been exposed by a data breach — meaning people who already lost work due to the pandemic might have to add identity theft to their difficulties.
The breach involved a third-party software vendor, Accellion, which the state Auditor’s Office uses to transmit files. The auditor has been looking into how Washington’s Employment Security Department lost hundreds of millions of dollars to fraudsters, including a Nigerian crime ring, who rushed to cash in on sweetened pandemic-related benefits by filing fake unemployment claims in the names of real state residents.
“I know this is one more worry for Washingtonians who have already faced unemployment in a year scarred by both job loss and a pandemic,” Auditor Pat McCarthy said in a news release. “I am sorry to share this news and add to their burdens.”
During a news conference later in the day, she called it “ironic” that files the agency obtained from the Employment Security Department to investigate the fraud would be subject to a breach, possibly opening victims to more fraud.
Those potentially affected include people who filed for unemployment benefits between Jan. 1 and Dec. 10, 2020. That includes many state workers as well as people who had fake unemployment claims submitted on their behalf.
It’s not clear how many people are affected because some would have filed multiple unemployment claims, but McCarthy said she believes it to be at least 1 million people — close to 1 in 7 Washington residents.
The data includes names, Social Security numbers, driver’s license numbers, bank information and place of employment. The Auditor’s Office says it is working with state cybersecurity officials, law enforcement and others to try to mitigate the damage.
McCarthy said state and federal law enforcement authorities are investigating. The state Attorney General’s Office is engaged too, she said.
Also potentially affected was information of both employees and around 100 clients of the Department of Children, Youth and Families. About 100 local governments and 25 other state agencies had information exposed in the breach, as well.
The Department of Social and Health Services, for example, reported eight information files involved. Of those, seven contained no client information, said Adolfo Capestany, senior director in the DSHS Office of Communications. One file contained personal information as part of an assessment of one client, he said.
And the city of Mukilteo learned it may be a victim, too.
Mayor Jennifer Gregerson said the state informed city officials that a file containing various documents related to a recently completed audit was among those potentially exposed. As a precaution, the city’s insurer was notified, she said.
When city staff did more digging, they discovered a second document may be involved, Gregerson said. It contained information from a 2019 review of Mukilteo’s IT security procedures.
“Based on what I’ve read and understand of the files involved, I’m not concerned about our files that appear to have been part of this,” she said. “There’s been no personal identifying info involved that we know of.”
In a statement Monday, Palo Alto, California-based Accellion called the attack “highly sophisticated” and said it targeted the company’s legacy secure file-transmitting software, a 20-year-old product called FTA. The Auditor’s Office said it had nearly completed transitioning from that product to the company’s new one at the end of the year when the breach occurred; since Dec. 31, the auditor’s office has been on the new system.
Other Accellion customers were also affected, including Australia’s securities regulator and New Zealand’s central bank.
McCarthy said the state learned of the attack Jan. 12 after Accellion made a general announcement regarding a security breach, but Accellion said it notified customers Dec. 23. It wasn’t until last week that the Auditor’s Office learned what files might have been accessed, McCarthy said.
The Auditor’s Office said it has used Accellion for the past 13 years, on a contract worth about $17,000 annually.
“We paid for, we expected and we deserve to have a secure system,” McCarthy said. “We had no indication, no inclination that this product was not secure.”
McCarthy said the agency is “working as fast as we can” to identify people who may have been affected.
The latest information on the breach, and resources for those affected, can be found on the agency web site at www.sao.wa.gov/breach2021.
Herald writer Jerry Cornfield contributed.
Talk to us
> Give us your news tips.
> Send us a letter to the editor.
> More Herald contact information.